CVE-2026-81934: Redis TLS pending-data list use-after-free
Published Aug 27, 2026
·Updated
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server.
Affected Software
1 affected component
Redis redis
Event History
Aug 27, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:18 PM
DescriptionSeverityWeakness
Jan 16, 58636
Event
via NVD·09:03 AM
Frequently Asked Questions
1
Which Redis deployments are exposed to this issue?
Deployments configured with TLS support are affected. The vulnerable code handles Redis's TLS pending-data list.
2
Does exploitation require Redis authentication or user interaction?
No. The issue is remotely exploitable by an unauthenticated attacker and requires no user interaction.
3
What could an attacker achieve?
An attacker may be able to execute arbitrary commands with the privileges of the Redis server, affecting confidentiality, integrity, and availability.
4
Which Redis releases contain fixes?
Fixed releases are Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.